blob: 1ed575bb9e435506e5c9a899b2daa16e7d8c9c71 [file] [log] [blame]
Vlad Tsyrklevich89c3c8c2017-10-11 20:35:01 +00001//===- FileAnalysis.h -------------------------------------------*- C++ -*-===//
2//
3// The LLVM Compiler Infrastructure
4//
5// This file is distributed under the University of Illinois Open Source
6// License. See LICENSE.TXT for details.
7//
8//===----------------------------------------------------------------------===//
9
10#ifndef LLVM_CFI_VERIFY_FILE_ANALYSIS_H
11#define LLVM_CFI_VERIFY_FILE_ANALYSIS_H
12
Mitch Phillips99fa1402017-10-23 20:25:19 +000013#include "llvm/ADT/DenseMap.h"
Vlad Tsyrklevich89c3c8c2017-10-11 20:35:01 +000014#include "llvm/BinaryFormat/ELF.h"
15#include "llvm/MC/MCAsmInfo.h"
16#include "llvm/MC/MCContext.h"
17#include "llvm/MC/MCDisassembler/MCDisassembler.h"
18#include "llvm/MC/MCInst.h"
19#include "llvm/MC/MCInstPrinter.h"
20#include "llvm/MC/MCInstrAnalysis.h"
21#include "llvm/MC/MCInstrDesc.h"
22#include "llvm/MC/MCInstrInfo.h"
23#include "llvm/MC/MCObjectFileInfo.h"
24#include "llvm/MC/MCRegisterInfo.h"
25#include "llvm/MC/MCSubtargetInfo.h"
26#include "llvm/Object/Binary.h"
27#include "llvm/Object/COFF.h"
28#include "llvm/Object/ELFObjectFile.h"
29#include "llvm/Object/ObjectFile.h"
30#include "llvm/Support/Casting.h"
31#include "llvm/Support/CommandLine.h"
32#include "llvm/Support/Error.h"
33#include "llvm/Support/MemoryBuffer.h"
34#include "llvm/Support/TargetRegistry.h"
35#include "llvm/Support/TargetSelect.h"
36#include "llvm/Support/raw_ostream.h"
37
38#include <functional>
39#include <set>
40#include <string>
41#include <unordered_map>
42
43namespace llvm {
44namespace cfi_verify {
45
46// Disassembler and analysis tool for machine code files. Keeps track of non-
47// sequential control flows, including indirect control flow instructions.
48class FileAnalysis {
49public:
50 // A metadata struct for an instruction.
51 struct Instr {
52 uint64_t VMAddress; // Virtual memory address of this instruction.
53 MCInst Instruction; // Instruction.
54 uint64_t InstructionSize; // Size of this instruction.
55 bool Valid; // Is this a valid instruction? If false, Instr::Instruction is
56 // undefined.
57 };
58
59 // Construct a FileAnalysis from a file path.
60 static Expected<FileAnalysis> Create(StringRef Filename);
61
62 // Construct and take ownership of the supplied object. Do not use this
63 // constructor, prefer to use FileAnalysis::Create instead.
64 FileAnalysis(object::OwningBinary<object::Binary> Binary);
65 FileAnalysis() = delete;
66 FileAnalysis(const FileAnalysis &) = delete;
67 FileAnalysis(FileAnalysis &&Other) = default;
68
Mitch Phillips5ff01cd2017-10-25 21:21:16 +000069 // Check whether the provided instruction is CFI protected in this file.
70 // Returns false if this instruction doesn't exist in this file, if it's not
71 // an indirect control flow instruction, or isn't CFI protected. Returns true
72 // otherwise.
73 bool isIndirectInstructionCFIProtected(uint64_t Address) const;
74
Vlad Tsyrklevich89c3c8c2017-10-11 20:35:01 +000075 // Returns the instruction at the provided address. Returns nullptr if there
76 // is no instruction at the provided address.
77 const Instr *getInstruction(uint64_t Address) const;
78
79 // Returns the instruction at the provided adress, dying if the instruction is
80 // not found.
81 const Instr &getInstructionOrDie(uint64_t Address) const;
82
83 // Returns a pointer to the previous/next instruction in sequence,
84 // respectively. Returns nullptr if the next/prev instruction doesn't exist,
85 // or if the provided instruction doesn't exist.
86 const Instr *getPrevInstructionSequential(const Instr &InstrMeta) const;
87 const Instr *getNextInstructionSequential(const Instr &InstrMeta) const;
88
Vlad Tsyrklevich0ee26322017-10-11 23:17:29 +000089 // Returns whether this instruction is used by CFI to trap the program.
90 bool isCFITrap(const Instr &InstrMeta) const;
91
92 // Returns whether this function can fall through to the next instruction.
93 // Undefined (and bad) instructions cannot fall through, and instruction that
94 // modify the control flow can only fall through if they are conditional
95 // branches or calls.
96 bool canFallThrough(const Instr &InstrMeta) const;
97
98 // Returns the definitive next instruction. This is different from the next
99 // instruction sequentially as it will follow unconditional branches (assuming
100 // they can be resolved at compile time, i.e. not indirect). This method
101 // returns nullptr if the provided instruction does not transfer control flow
102 // to exactly one instruction that is known deterministically at compile time.
103 // Also returns nullptr if the deterministic target does not exist in this
104 // file.
105 const Instr *getDefiniteNextInstruction(const Instr &InstrMeta) const;
106
107 // Get a list of deterministic control flows that lead to the provided
108 // instruction. This list includes all static control flow cross-references as
109 // well as the previous instruction if it can fall through.
110 std::set<const Instr *>
111 getDirectControlFlowXRefs(const Instr &InstrMeta) const;
112
Vlad Tsyrklevich89c3c8c2017-10-11 20:35:01 +0000113 // Returns whether this instruction uses a register operand.
114 bool usesRegisterOperand(const Instr &InstrMeta) const;
115
116 // Returns the list of indirect instructions.
117 const std::set<uint64_t> &getIndirectInstructions() const;
118
119 const MCRegisterInfo *getRegisterInfo() const;
120 const MCInstrInfo *getMCInstrInfo() const;
121 const MCInstrAnalysis *getMCInstrAnalysis() const;
122
123protected:
124 // Construct a blank object with the provided triple and features. Used in
125 // testing, where a sub class will dependency inject protected methods to
126 // allow analysis of raw binary, without requiring a fully valid ELF file.
127 FileAnalysis(const Triple &ObjectTriple, const SubtargetFeatures &Features);
128
129 // Add an instruction to this object.
130 void addInstruction(const Instr &Instruction);
131
132 // Disassemble and parse the provided bytes into this object. Instruction
133 // address calculation is done relative to the provided SectionAddress.
134 void parseSectionContents(ArrayRef<uint8_t> SectionBytes,
135 uint64_t SectionAddress);
136
137 // Constructs and initialises members required for disassembly.
138 Error initialiseDisassemblyMembers();
139
140 // Parses code sections from the internal object file. Saves them into the
141 // internal members. Should only be called once by Create().
142 Error parseCodeSections();
143
144private:
145 // Members that describe the input file.
146 object::OwningBinary<object::Binary> Binary;
147 const object::ObjectFile *Object = nullptr;
148 Triple ObjectTriple;
149 std::string ArchName;
150 std::string MCPU;
151 const Target *ObjectTarget = nullptr;
152 SubtargetFeatures Features;
153
154 // Members required for disassembly.
155 std::unique_ptr<const MCRegisterInfo> RegisterInfo;
156 std::unique_ptr<const MCAsmInfo> AsmInfo;
157 std::unique_ptr<MCSubtargetInfo> SubtargetInfo;
158 std::unique_ptr<const MCInstrInfo> MII;
159 MCObjectFileInfo MOFI;
160 std::unique_ptr<MCContext> Context;
161 std::unique_ptr<const MCDisassembler> Disassembler;
162 std::unique_ptr<const MCInstrAnalysis> MIA;
163 std::unique_ptr<MCInstPrinter> Printer;
164
165 // A mapping between the virtual memory address to the instruction metadata
166 // struct.
167 std::map<uint64_t, Instr> Instructions;
168
169 // Contains a mapping between a specific address, and a list of instructions
170 // that use this address as a branch target (including call instructions).
Mitch Phillips99fa1402017-10-23 20:25:19 +0000171 DenseMap<uint64_t, std::vector<uint64_t>> StaticBranchTargetings;
Vlad Tsyrklevich89c3c8c2017-10-11 20:35:01 +0000172
173 // A list of addresses of indirect control flow instructions.
174 std::set<uint64_t> IndirectInstructions;
175};
176
177class UnsupportedDisassembly : public ErrorInfo<UnsupportedDisassembly> {
178public:
179 static char ID;
Mitch Phillipsd9af3832017-10-23 20:54:01 +0000180 std::string Text;
181
182 UnsupportedDisassembly(StringRef Text);
Vlad Tsyrklevich89c3c8c2017-10-11 20:35:01 +0000183
184 void log(raw_ostream &OS) const override;
185 std::error_code convertToErrorCode() const override;
186};
187
188} // namespace cfi_verify
189} // namespace llvm
190
191#endif // LLVM_CFI_VERIFY_FILE_ANALYSIS_H